Description: BEA has reported a security issue in WebLogic, which may provide users access to the wrong profile.
The problem occurs on systems using client certificates to identify users. When a Web Services fat client connects to the same WebLogic Server using different client certificates, it might use the wrong identity on subsequent connections.
The problem affects WebLogic Server and Express 7.0.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.